kevmap

TechniquesT1078 › T1078.004

T1078.004 Cloud Accounts

stealth · persistence · privilege escalation · initial access — IaaS, Identity Provider, Office Suite, SaaS · attack.mitre.org · JSON

1
MITRE detection strategy
4
analytics
41
Sigma rules tagged attack.t1078.004
1
KEV CVEs mapped here
<p>Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.</p><p>Service or user accounts may be targeted by adversaries through Brute Force, Phishing, or various other means to gain access to the environment. Federated or synced accounts may be a pathway for the adversary to affect both on-premises systems and cloud environments - for example, by leveraging shared credentials to log onto Remote Services. High privileged cloud accounts, whether federated, synced, or cloud-only, may also allow pivoting to on-premises environments by leveraging SaaS-based Software Deployment Tools to run commands on hybrid-joined devices.</p><p>An adversary may create long lasting Additional Cloud Credentials on a compromised cloud account to maintain persistence in the environment. Such credentials may also be used to bypass security controls such as multi-factor authentication.</p><p>Cloud accounts may also be able to assume Temporary Elevated Cloud Access or other privileges through various means within the environment. Misconfigurations in role assignments or role assumption policies may allow an adversary to use these mechanisms to leverage permissions outside the intended scope of the account. Such over privileged accounts may be used to harvest sensitive data from online storage accounts and databases through Cloud API or other methods. For example, in Azure environments, adversaries may target Azure Managed Identities, which allow associated Azure resources to request access tokens. By compromising a resource with an attached Managed Identity, such as an Azure VM, adversaries may be able to Steal Application Access Tokens to move laterally across the cloud environment.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2024-53704SonicWall SonicOS primary impact Mapped2025-02-18

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1078.004

Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik' · 2022-06-02 · logsource: product=azure service=auditlogs · 0055ad1f-be85-4798-83cf-a6da17c993b3
Detects when a configuration change is made to an applications URI. URIs for domain names that no longer exist (dangling URIs), not using HTTPS, wildcards at the end of the domain, URIs that are no unique to that app, or URIs that point to domains you do not control should be investigated.
Techniques: T1528T1078.004
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H' · 2022-08-09 · logsource: product=azure service=auditlogs · 039a7469-0296-4450-84c0-f6966b16dc6d
Detects when a PIM elevation is approved or denied. Outside of normal operations should be investigated.
Techniques: T1078.004
Author: Austin Songer @austinsonger · 2021-11-26 (modified 2022-08-23) · logsource: product=azure service=activitylogs · 09438caa-07b1-4870-8405-1dbafe3dad95
Detects when a user has been elevated to manage all Azure Subscriptions. This change should be investigated immediately if it isn't planned. This setting could allow an attacker access to Azure subscriptions in your environment.
Techniques: T1078.004
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H' · 2022-08-10 · logsource: product=azure service=auditlogs · 0b4b72e3-4c53-4d5b-b198-2c58cfef39a9
Detects when a user that doesn't have permissions to invite a guest user attempts to invite one.
Techniques: T1078.004
Author: Michael Epping, '@mepples21' · 2022-06-28 · logsource: product=azure service=auditlogs · 11c767ae-500b-423b-bae3-b234450736ed
Monitor and alert for users added to device admin roles.
Techniques: T1078.004
Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik' · 2022-06-02 · logsource: product=azure service=auditlogs · 1b45b0d1-773f-4f23-aedc-814b759563b1
Detects when a configuration change is made to an applications AppID URI.
Techniques: T1552T1078.004
Author: MikeDuddington, '@dudders1' · 2022-07-28 · logsource: product=azure service=signinlogs · 28870ae4-6a13-4616-bd1a-235a7fad7458
Detect failed authentications from countries you do not operate out of.
Techniques: T1078.004T1110
Author: MikeDuddington, '@dudders1' · 2022-07-27 · logsource: product=azure service=signinlogs · 28eea407-28d7-4e42-b0be-575d5ba60b2c
Detect when users are authenticating without MFA being required.
Techniques: T1078.004T1556.006
Author: Romain Gaillard (@romain-gaillard) · 2024-07-29 · logsource: product=github service=audit · 2f575940-d85e-4ddc-af13-17dad6f1a0ef
Detects when changes are made to the SSH certificate configuration of the organization.
Techniques: T1078.004
AWS Console Login Monitoring mediumexperimental
Author: Ivan Saakov · 2025-10-19 · logsource: product=aws service=cloudtrail · 313e72de-0c0d-4d65-8c95-87f4d546eceb
Detects AWS console logins from countries and IP addresses that are not recognized as legitimate for the organization. This alert can help identify potential unauthorized access attempts from unusual locations, which may indicate compromised credentials or malicious activity.
Techniques: T1078.004
Author: YochanaHenderson, '@Yochana-H' · 2022-08-03 · logsource: product=azure service=auditlogs · 340ee172-4b67-4fb4-832f-f961bdc1f3aa
Detect when a user has reset their password in Azure AD
Techniques: T1078.004
Author: Tom Kluter · 2026-04-28 · logsource: product=gcp service=google_workspace.login · 38360161-76c4-4283-842e-efcf997dafc8
Detects Google Workspace login activity that's classified as suspicious by Google.
Techniques: T1078.004
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H' · 2022-08-06 · logsource: product=azure service=auditlogs · 49a268a4-72f4-4e38-8a7b-885be690c5b5
Detects when a user is added to a privileged role.
Techniques: T1078.004
Author: Yochana Henderson, '@Yochana-H' · 2022-06-17 · logsource: product=azure service=signinlogs · 4afac85c-224a-4dd7-b1af-8da40e1c60bd
Detects when an account is disabled or blocked for sign in but tried to log in
Techniques: T1078.004
Author: Michael Epping, '@mepples21' · 2022-06-28 (modified 2022-10-05) · logsource: product=azure service=signinlogs · 4d136857-6a1a-432a-82fc-5dd497ee5e7c
Monitor and alert for Sign-ins by unknown devices from non-Trusted locations.
Techniques: T1078.004
Author: Michael Epping, '@mepples21' · 2022-06-28 · logsource: product=azure service=signinlogs · 4f77e1d7-3982-4ee0-8489-abf2d6b75284
Monitor and alert for sign-ins where the device was non-compliant.
Techniques: T1078.004
Author: Harjot Singh, '@cyb3rjy0t' · 2023-03-20 · logsource: product=azure service=signinlogs · 53bb4f7f-48a8-4475-ac30-5a82ddfdf6fc
Detects successful authentication from potential clients using legacy authentication via user agent strings. This could be a sign of MFA bypass using a password spray attack.
Techniques: T1078.004T1110
Author: AlertIQ · 2021-10-10 (modified 2022-12-18) · logsource: product=azure service=signinlogs · 5496ff55-42ec-4369-81cb-00f417029e25
Identifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.
Author: Michael Epping, '@mepples21' · 2022-06-28 · logsource: product=azure service=signinlogs · 5afa454e-030c-4ab4-9253-a90aa7fcc581
Monitor and alert for device registration or join events where MFA was not performed.
Techniques: T1078.004
Author: MikeDuddington, '@dudders1' · 2022-06-30 (modified 2026-05-08) · logsource: product=azure service=signinlogs · 5f521e4b-0105-4b72-845b-2198a54487b9
Detect when users in your Azure AD tenant are authenticating to other Azure AD Tenants.
Techniques: T1078.004
Author: Yochana Henderson, '@Yochana-H' · 2022-06-17 · logsource: product=azure service=signinlogs · 60f6535a-760f-42a9-be3f-c9a0a025906e
Alert on when legacy authentication has been used on an account
Techniques: T1078.004T1110
Author: Muhammad Faisal (@faisalusuf) · 2024-02-25 · logsource: product=bitbucket service=audit · 70ed1d26-0050-4b38-a599-92c53d57d45a
Detects user authentication failure events. Please note that this rule can be noisy and it is recommended to use with correlation based on "author.name" field.
Techniques: T1078.004T1110
Author: Thuya@Hacktilizer, Ivan Saakov · 2025-10-18 (modified 2025-10-21) · logsource: product=aws service=cloudtrail · 77caf516-34e5-4df9-b4db-20744fea0a60
Detects successful AWS console logins that were performed without Multi-Factor Authentication (MFA). This alert can be used to identify potential unauthorized access attempts, as logging in without MFA can indicate compromised credentials or misconfigured security settings.
Techniques: T1078.004
Author: vitaliy0x1 · 2020-01-21 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · 8ad1600d-e9dc-4251-b0ee-a65268f29add
Detects AWS root account usage
Techniques: T1078.004
Author: MikeDuddington, '@dudders1' · 2022-07-28 (modified 2026-05-08) · logsource: product=azure service=signinlogs · 8c944ecb-6970-4541-8496-be554b8e2846
Detect successful authentications from countries you do not operate out of.
Techniques: T1078.004T1110
Author: MikeDuddington, '@dudders1' · 2022-06-30 · logsource: product=azure service=auditlogs · 8dee7a0d-43fd-4b3c-8cd1-605e189d195e
Detects the change of user type from "Guest" to "Member" for potential elevation of privilege.
Techniques: T1078.004
Author: AlertIQ · 2021-10-10 (modified 2022-12-25) · logsource: product=azure service=signinlogs · 908655e0-25cf-4ae1-b775-1c8ce9cf43d8
Detect failed attempts to sign in to disabled accounts.
Techniques: T1078.004
Author: AlertIQ · 2021-10-10 (modified 2022-12-25) · logsource: product=azure service=signinlogs · 9a60e676-26ac-44c3-814b-0c2a8b977adf
Detect access has been blocked by Conditional Access policies. The access policy does not allow token issuance which might be sights≈ of unauthorizeed login to valid accounts.
Techniques: T1110T1078.004
Author: Michael Epping, '@mepples21' · 2022-06-28 · logsource: product=azure service=auditlogs · a0413867-daf3-43dd-9245-734b3a787942
Monitor and alert for Bitlocker key retrieval.
Techniques: T1078.004
Author: kelnage · 2023-09-07 (modified 2026-04-27) · logsource: product=okta service=okta · a0b38b70-3cb5-484b-a4eb-c4d8e7bcc0a9
Detects when Okta identifies new activity in the Admin Console.
Techniques: T1078.004
Author: Yochana Henderson, '@Yochana-H' · 2022-06-01 · logsource: product=azure service=signinlogs · b4a6d707-9430-4f5f-af68-0337f52d5c42
Define a baseline threshold for failed sign-ins due to Conditional Access failures
Techniques: T1110T1078.004
Author: Ivan Saakov · 2024-12-19 · logsource: product=aws service=cloudtrail · ccd6a6c8-bb4e-4a91-9d2a-07e632819374
Detects the deletion of an AWS SAML provider, potentially indicating malicious intent to disrupt administrative or security team access. An attacker can remove the SAML provider for the information security team or a team of system administrators, to make it difficult for them to work and investigate at the time of the attack and after it.
Techniques: T1078.004T1531
Author: daniel.bohannon@permiso.io (@danielhbohannon) · 2023-05-17 · logsource: product=aws service=cloudtrail · db014773-7375-4f4e-b83b-133337c0ffee
Detects S3 browser utility creating Inline IAM policy containing default S3 bucket name placeholder value of "<YOUR-BUCKET-NAME>".
Techniques: T1059.009T1078.004
Author: daniel.bohannon@permiso.io (@danielhbohannon) · 2023-05-17 · logsource: product=aws service=cloudtrail · db014773-b1d3-46bd-ba26-133337c0ffee
Detects S3 Browser utility performing reconnaissance looking for existing IAM Users without a LoginProfile defined then (when found) creating a LoginProfile.
Techniques: T1059.009T1078.004
Author: daniel.bohannon@permiso.io (@danielhbohannon) · 2023-05-17 · logsource: product=aws service=cloudtrail · db014773-d9d9-4792-91e5-133337c0ffee
Detects S3 Browser utility creating IAM User or AccessKey.
Techniques: T1059.009T1078.004
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H' · 2022-08-09 · logsource: product=azure service=auditlogs · db6c06c4-bf3b-421c-aa88-15672b88c743
Detects when changes are made to PIM roles
Techniques: T1078.004
Author: AlertIQ · 2022-03-24 · logsource: product=azure service=signinlogs · e40f4962-b02b-4192-9bfe-245f7ece1f99
User has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H', Tim Shelton · 2022-08-11 (modified 2022-08-16) · logsource: product=azure service=auditlogs · f7b5b004-dece-46e4-a4a5-f6fd0e1c6947
Detects when a new admin is created.
Techniques: T1078.004
Author: Muhammad Faisal (@faisalusuf) · 2023-01-27 · logsource: product=github service=audit · f8ed0e8f-7438-4b79-85eb-f358ef2fbebd
A self-hosted runner is a system that you deploy and manage to execute jobs from GitHub Actions on GitHub.com. This rule detects changes to self-hosted runners configurations in the environment. The self-hosted runner configuration changes once detected, it should be validated from GitHub UI because the log entry may not provide full context.
Author: Muhammad Faisal (@faisalusuf) · 2023-01-20 · logsource: product=github service=audit · f9405037-bc97-4eb7-baba-167dad399b83
Detects when a user creates action secret for the organization, environment, codespaces or repository.
Techniques: T1078.004
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H' · 2022-08-10 · logsource: product=azure service=auditlogs · fa84aaf5-8142-43cd-9ec2-78cfebf878ce
Detects when a temporary access pass (TAP) is added to an account. TAPs added to priv accounts should be investigated
Techniques: T1078.004

Rules tagged at the parent level (attack.t1078) 56

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-03 · logsource: product=azure service=riskdetection · 128faeef-79dd-44ca-b43c-a9e236a60f49
Detects sign-in with properties that are unfamiliar to the user. The detection considers past sign-in history to look for anomalous sign-ins.
Techniques: T1078
Author: Josh Nickels, Marius Rothenbücher · 2025-01-08 · logsource: product=m365 service=audit · 13f2d3f5-6497-44a7-bf5f-dc13ffafe5dc
Detects a successful login to the Microsoft Intune Company Portal which could allow bypassing Conditional Access Policies and InTune device trust using a tool like TokenSmith.
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-03 · logsource: product=azure service=riskdetection · 1a41023f-1e70-4026-921a-4d9341a9038e
Identifies two sign-ins originating from geographically distant locations, where at least one of the locations may also be atypical for the user, given past behavior.
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik' · 2022-06-01 · logsource: product=azure service=signinlogs · 248649b7-d64f-46f0-9fb2-a52774166fb5
Device code flow is an OAuth 2.0 protocol flow specifically for input constrained devices and is not used in all environments. If this type of flow is seen in the environment and not being used in an input constrained device scenario, further investigation is warranted. This can be a misconfigured application or potentially something malicious.
Techniques: T1078
Author: Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity) · 2023-01-19 (modified 2024-03-11) · logsource: product=windows service=security · 259a9cdf-c4dd-4fa2-b243-2269e5ab18a2
Detects successful logon from public IP address via RDP. This can indicate a publicly-exposed RDP port.
Techniques: T1133T1078T1110
Author: Austin Songer · 2021-09-06 (modified 2022-06-08) · logsource: product=azure service=auditlogs · 352a54e1-74ba-4929-9d47-8193d67aba1e
Identifies when an user or application modified the federation settings on the domain.
Techniques: T1078
Author: jamesc-grafana · 2024-07-11 · logsource: product=aws service=cloudtrail · 352a918a-34d8-4882-8470-44830c507aa3
Detects when an instance identity has taken an action that isn't inside SSM. This can indicate that a compromised EC2 instance is being used as a pivot point.
Techniques: T1078T1078.002
Author: elhoim · 2022-09-09 (modified 2023-01-04) · logsource: product=windows service=security · 39698b3f-da92-4bc6-bfb5-645a98386e45
Detects suspicious computer name samtheadmin-{1..100}$ generated by hacktool
Techniques: T1078
CVE tags: CVE-2021-42278CVE-2021-42287
Author: Florian Roth (Nextron Systems) · 2017-03-17 (modified 2023-12-15) · logsource: product=windows service=security · 3ff152b2-1388-4984-9cd9-a323323fdadf
Detects interactive console logons to Server Systems
Techniques: T1078
Author: MikeDuddington, '@dudders1' · 2022-07-28 (modified 2026-05-09) · logsource: product=azure service=auditlogs · 4ad97bf5-a514-41a4-abd3-4f3455ad4865
Detects guest users being invited to tenant by non-approved inviters
Techniques: T1078
Author: Tim Brown · 2023-01-09 · logsource: product=cisco service=ldp · 50e606bf-04ce-4ca7-9d54-3449494bbd4b
Detects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels
Techniques: T1078T1110T1557
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · 512cff7a-683a-43ad-afe0-dd398e872f36
Detects instances where a Telnet service on an OpenCanary node has had a login attempt.
Techniques: T1133T1078
Author: Mark Morowczynski '@markmorow', Bailey Bercik '@baileybercik' · 2022-06-01 · logsource: product=azure service=signinlogs · 55695bc0-c8cf-461f-a379-2535f563c854
Resource owner password credentials (ROPC) should be avoided if at all possible as this requires the user to expose their current password credentials to the application directly. The application then uses those credentials to authenticate the user against the identity provider.
Techniques: T1078
Author: Tim Brown · 2023-01-09 (modified 2023-01-23) · logsource: product=cisco service=bgp · 56fa3cd6-f8d6-4520-a8c7-607292971886
Detects BGP failures which may be indicative of brute force attacks to manipulate routing
Techniques: T1078T1110T1557
Author: Harjot Singh, '@cyb3rjy0t' · 2023-01-10 (modified 2025-07-02) · logsource: product=azure service=signinlogs · 572b12d4-9062-11ed-a1eb-0242ac120002
Detects risky authentication from a non AD registered device without MFA being required.
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-14 · logsource: product=azure service=pim · 58af08eb-f9e1-43c8-9805-3ad9b0482bd8
Identifies when an organization doesn't have the proper license for PIM and is out of compliance.
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-14 · logsource: product=azure service=pim · 645fd80d-6c07-435b-9e06-7bc1b5656cba
Identifies when the same privilege role has multiple activations by the same user.
Techniques: T1078
Author: Austin Songer @austinsonger · 2021-11-25 (modified 2022-12-18) · logsource: product=gcp service=gcp.audit · 6ad91e31-53df-4826-bd27-0166171c8040
Identifies when an admission controller is executed in GCP Kubernetes. A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server. The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster. An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster. For example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials. An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.
Author: Mark Morowczynski '@markmorow', MikeDuddington, '@dudders1', Tim Shelton · 2022-08-11 (modified 2022-08-18) · logsource: product=azure service=auditlogs · 6f583da0-3a90-4566-a4ed-83c09fe18bbf
Detects when an account was created and deleted in a short period of time.
Techniques: T1078
Author: Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity) · 2023-01-19 (modified 2024-03-11) · logsource: product=windows service=security · 78d5cab4-557e-454f-9fb9-a222bd0d5edc
Detects successful logon from public IP address via SMB. This can indicate a publicly-exposed SMB port.
Techniques: T1133T1078T1110
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-14 · logsource: product=azure service=pim · 7bbc309f-e2b1-4eb1-8369-131a367d67d3
Identifies an event where there are there are too many accounts assigned the Global Administrator role.
Techniques: T1078
Author: Sohan G (D4rkCiph3r) · 2023-08-22 · logsource: product=macos category=process_creation · 821bcf4d-46c7-4b87-bc57-9509d3ba7c11
Detects attempts to enable the root account via "dsenableroot"
Author: Austin Songer @austinsonger · 2021-11-26 (modified 2022-12-18) · logsource: product=azure service=signinlogs · 8366030e-7216-476b-9927-271d79f13cf3
Detects when there is a interruption in the authentication process.
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-14 · logsource: product=azure service=pim · 8c6ec464-4ae4-43ac-936a-291da66ed13d
Identifies when a user has been assigned a privilege role and are not using that role.
Techniques: T1078
AWS Key Pair Import Activity mediumexperimental
Author: Ivan Saakov · 2024-12-19 · logsource: product=aws service=cloudtrail · 92f84194-8d9a-4ee0-8699-c30bfac59780
Detects the import of SSH key pairs into AWS EC2, which may indicate an attacker attempting to gain unauthorized access to instances. This activity could lead to initial access, persistence, or privilege escalation, potentially compromising sensitive data and operations.
Techniques: T1078
Author: oscd.community, Teymur Kheirkhabarov @HeirhabarovT, Zach Stanford @svch0st, Tim Shelton · 2020-10-05 (modified 2022-08-03) · logsource: product=windows service=security · 941e5c45-cda7-4864-8cea-bbb7458d194a
Detects suspicious processes logging on with explicit credentials
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-03 · logsource: product=azure service=riskdetection · 944f6adb-7a99-4c69-80c1-b712579e93e6
Indicates anomalous behavior based on suspicious sign-in activity across multiple tenants from different countries in the same browser
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-14 · logsource: product=azure service=pim · 94a66f46-5b64-46ce-80b2-75dcbe627cc0
Identifies when a privilege role can be activated without performing mfa.
Techniques: T1078
Author: Florian Roth (Nextron Systems) · 2017-02-19 (modified 2025-10-17) · logsource: product=windows service=security · 9eb99343-d336-4020-a3cd-67f3819e68ee
This method uses uncommon error codes on failed logons to determine suspicious activity and tampering with accounts that have been disabled or somehow restricted.
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-07 · logsource: product=azure service=riskdetection · a2cb56ff-4f46-437a-a0fa-ffa4d1303cba
Indicates user activity that is unusual for the user or consistent with known attack patterns.
Techniques: T1078
Author: Tim Brown · 2023-01-09 (modified 2023-01-23) · logsource: product=huawei service=bgp · a557ffe6-ac54-43d2-ae69-158027082350
Detects BGP failures which may be indicative of brute force attacks to manipulate routing.
Techniques: T1078T1110T1557
Author: Austin Songer @austinsonger · 2021-11-25 (modified 2022-12-18) · logsource: product=azure service=activitylogs · a61a3c56-4ce2-4351-a079-88ae4cbd2b58
Identifies when an admission controller is executed in Azure Kubernetes. A Kubernetes Admission controller intercepts, and possibly modifies, requests to the Kubernetes API server. The behavior of this admission controller is determined by an admission webhook (MutatingAdmissionWebhook or ValidatingAdmissionWebhook) that the user deploys in the cluster. An adversary can use such webhooks as the MutatingAdmissionWebhook for obtaining persistence in the cluster. For example, attackers can intercept and modify the pod creation operations in the cluster and add their malicious container to every created pod. An adversary can use the webhook ValidatingAdmissionWebhook, which could be used to obtain access credentials. An adversary could use the webhook to intercept the requests to the API server, record secrets, and other sensitive information.
Author: Tim Brown · 2023-01-09 (modified 2023-01-23) · logsource: product=juniper service=bgp · a7c0ae48-8df8-42bf-91bd-2ea57e2f9d43
Detects juniper BGP missing MD5 digest. Which may be indicative of brute force attacks to manipulate routing.
Techniques: T1078T1110T1557
New Country hightest
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-03 · logsource: product=azure service=riskdetection · adf9f4d2-559e-4f5c-95be-c28dff0b1476
Detects sign-ins from new countries. The detection considers past activity locations to determine new and infrequent locations.
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H' · 2022-08-09 · logsource: product=azure service=auditlogs · aeaef14c-e5bf-4690-a9c8-835caad458bd
Detects when PIM alerts are set to disabled.
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-14 · logsource: product=azure service=pim · b1bc08d1-8224-4758-a0e6-fbcfc98c73bb
Identifies when a privilege role assignment has taken place outside of PIM and may indicate an attack.
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-03 · logsource: product=azure service=riskdetection · b2572bf9-e20a-4594-b528-40bde666525a
Identifies user activities originating from geographically distant locations within a time period shorter than the time it takes to travel from the first location to the second.
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-03 · logsource: product=azure service=riskdetection · be4d9c86-d702-4030-b52e-c7859110e5e8
Identifies that users were active from an IP address that has been identified as an anonymous proxy IP address.
Techniques: T1078
Author: Austin Songer @austinsonger · 2021-08-23 (modified 2022-10-09) · logsource: product=m365 service=threat_management · c191e2fa-f9d6-4ccf-82af-4f2aba08359f
Detects when a Microsoft Cloud App Security reported when a user signs into your sanctioned apps from a risky IP address.
Techniques: T1078
Author: Florian Roth (Nextron Systems) · 2017-03-14 (modified 2021-01-17) · logsource: product=windows service=security · c265cf08-3f99-46c1-8d59-328247057d57
Detects the addition of a new member to the local administrator group, which could be legitimate activity or a sign of privilege escalation activity
Techniques: T1078T1098
Author: Mark Morowczynski '@markmorow', MikeDuddington, '@dudders1' · 2022-08-11 (modified 2023-12-15) · logsource: product=azure service=auditlogs · c98184ba-4a27-4e10-b7b7-da48e71f4d25
Detects accounts that are created or deleted by non-approved users.
Techniques: T1078
Author: Austin Songer @austinsonger · 2021-11-26 (modified 2022-12-25) · logsource: product=azure service=auditlogs · ca9bf243-465e-494a-9e54-bf9fc239057d
Detects when a user has been elevated to manage all Azure Subscriptions. This change should be investigated immediately if it isn't planned. This setting could allow an attacker access to Azure subscriptions in your environment.
Techniques: T1078
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · cd55f721-5623-4663-bd9b-5229cab5237d
Detects instances where an SSH service on an OpenCanary node has had a connection attempt.
Techniques: T1133T1021T1078
Author: Mark Morowczynski '@markmorow', Yochana Henderson, '@Yochana-H' · 2022-08-11 (modified 2023-12-15) · logsource: product=azure service=signinlogs · cf1e5687-84e1-41af-97a9-158094efef53
Detects failed sign-in due to user not meeting expected controls for adminitrators
Techniques: T1078
Author: Tim Shelton (HAWK.IO) · 2021-12-09 (modified 2023-02-21) · logsource: product=windows category=process_creation · d4498716-1d52-438f-8084-4a603157d131
Detects a when net.exe is called with a password in the command line
Techniques: T1021.002T1078
Author: Sohan G (D4rkCiph3r) · 2023-02-18 · logsource: product=macos category=process_creation · d7329412-13bd-44ba-a072-3387f804a106
Detects attempts to enable the guest account using the sysadminctl utility
Techniques: T1078T1078.001
Author: Austin Songer @austinsonger · 2020-07-06 (modified 2021-11-27) · logsource: product=m365 service=threat_management · d7eab125-5f94-43df-8710-795b80fa1189
Detects when a Microsoft Cloud App Security reported a risky sign-in attempt due to a login associated with an impossible travel.
Techniques: T1078
Author: frack113 · 2022-02-21 · logsource: product=windows category=ps_module · e3818659-5016-4811-a73c-dde4679169d2
The Reset-ComputerMachinePassword cmdlet changes the computer account password that the computers use to authenticate to the domain controllers in the domain. You can use it to reset the password of the local computer.
Techniques: T1078
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-14 · logsource: product=azure service=pim · e402c26a-267a-45bd-9615-bd9ceda6da85
Identifies when an account hasn't signed in during the past n number of days.
Techniques: T1078
Author: Tom Kluter · 2026-04-28 · logsource: product=gcp service=google_workspace.login · eafe6f2b-cfec-4612-aec2-49563c33a087
Detects a login attempt in Google Workspace flagged as a potential attack by a government-backed threat actor
Techniques: T1078
Author: Raphaël CALVET, @MetallicHack · 2021-10-04 (modified 2026-04-30) · logsource: product=azure service=auditlogs · ebbeb024-5b1d-4e16-9c0c-917f86c708a7
User Added to an Administrator's Azure AD Role
Techniques: T1098.003T1078
Author: kelnage · 2024-07-11 · logsource: product=kubernetes service=audit · eed82177-38f5-4299-8a76-098d50d225ab
Detects when a modification (create, update or replace) action is taken that affects mutating or validating webhook configurations, as they can be used by an adversary to achieve persistence or exfiltrate access credentials.
Author: MikeDuddington, '@dudders1' · 2022-07-28 (modified 2026-05-08) · logsource: product=azure service=signinlogs · f272fb46-25f2-422c-b667-45837994980f
Detect when authentications to important application(s) only required single-factor authentication
Techniques: T1078
Author: Austin Songer · 2021-09-22 (modified 2022-12-18) · logsource: product=aws service=cloudtrail · f43f5d2f-3f2a-4cc8-b1af-81fde7dbaf0e
Identifies when suspicious SAML activity has occurred in AWS. An adversary could gain backdoor access via SAML.
Author: NVISO · 2020-05-06 (modified 2024-03-11) · logsource: product=windows service=security · f88e112a-21aa-44bd-9b01-6ee2a2bbbed1
Detects a failed logon attempt from a public IP. A login from a public IP can indicate a misconfigured firewall or network boundary.
Techniques: T1078T1190T1133
Author: Security Onion Solutions · 2024-03-08 · logsource: product=opencanary category=application · ff7139bc-fdb1-4437-92f2-6afefe8884cb
Detects instances where an SSH service on an OpenCanary node has had a login attempt.
Techniques: T1133T1021T1078